generated: '2026-09-04' method: derived source: openapi/ (26 first-party OpenAPI 3.1 documents harvested from developer.barclays.com) note: 'Barclays runs three distinct API conventions under one portal: UK Open Banking (OBIE Read/Write, x-fapi-* headers), Barclays Bank Ireland (Berlin Group NextGenPSD2, PSU-*/TPP-* headers), and Barclaycard US (Correlation-ID + bearer token). Nothing about the three is unified, so an agent has to detect which family it is calling before it can build a request.' auth: style: OAuth 2.0 bearer token families: - family: UK Open Banking (BUK) schemes: - TPPOAuth2Security (client_credentials) - PSUOAuth2Security (authorization_code) transport_security: mTLS with an Open Banking-issued transport certificate (see conformance/) headers: - Authorization - x-fapi-auth-date - x-fapi-customer-ip-address - x-fapi-interaction-id - x-customer-user-agent - family: Barclays Bank Ireland (Berlin Group NextGenPSD2) schemes: - OAuth 2.0 / PSU redirect (SCA) headers: - X-Request-ID - Consent-ID - PSU-ID - PSU-ID-Type - PSU-IP-Address - PSU-Device-ID - TPP-Redirect-URI - Digest - Signature - TPP-Signature-Certificate - family: Barclaycard US schemes: - ExternalTiaaUsCCAuth (client_credentials) - InternalTiaaUsRopcAuth headers: - Authorization - Correlation-ID - Content-Type - X-Channel-Id see: authentication/barclays-authentication.yml, scopes/barclays-scopes.yml idempotency: coverage: partial mechanism: x-idempotency-key request header declared_as: components.parameters.x-idempotency-key scope: - 'Payment Initiation: CreateDomesticPayments' - 'Payment Initiation: CreateDomesticPaymentConsents' - 'Payment Initiation: CreateDomesticScheduledPayments' - 'Payment Initiation: CreateDomesticScheduledPaymentConsents' - 'Payment Initiation: CreateDomesticStandingOrders' - 'Payment Initiation: CreateDomesticStandingOrderConsents' - 'Payment Initiation: CreateInternationalPayments' - 'Payment Initiation: CreateInternationalPaymentConsents' - 'Payment Initiation: CreateInternationalScheduledPayments' - 'Payment Initiation: CreateInternationalScheduledPaymentConsents' - 'Payment Initiation: CreateInternationalStandingOrders' - 'Payment Initiation: CreateInternationalStandingOrderConsents' - 'Payment Initiation: CreateFilePayments' - 'Payment Initiation: CreateFilePaymentConsents' - 'Payment Initiation: CreateFilePaymentConsentsConsentIdFile' - 'Variable Recurring Payment: domesticVrpPost' - 'Variable Recurring Payment: domesticVrpConsentsPost' - 'Variable Recurring Payment: domesticVrpConsentsPut' - 'Variable Recurring Payment: domesticVrpConsentsPatch' measured: mutating_operations: 64 operations_with_idempotency_key: 19 apis_covered: 2 apis_total: 26 retention: null note: 19 of 64 mutating operations across the estate declare x-idempotency-key, and all 19 sit in the two UK Open Banking payment APIs where OBIE mandates the header. The Barclays Bank Ireland payment writes and every Barclaycard US write — card applications, card controls, payments, account management — declare no replay protection at all. Barclays publishes no key-retention window. reversibility: grade: documented note: Every reversal Barclays publishes is a consent revocation, not a transaction reversal. A TPP can DELETE a consent and stop future access or future payments; nothing in the 26 published contracts cancels, refunds, voids or reverses a payment that has already executed, and no operation declares a window inside which a reversal is accepted. Barclaycard US has no reversal operation of any kind. Grade is documented rather than verified because no stated window exists. reversals: - operationId: DeleteAccountAccessConsentsConsentId api: Account and Transactions method: delete path: /account-access-consents/{consentId} reverses: account access consent window: null - operationId: DeleteFundsConfirmationConsentsConsentId api: Confirmation of Funds method: delete path: /funds-confirmation-consents/{consentId} reverses: funds confirmation consent window: null - operationId: domesticVrpConsentsDelete api: Variable Recurring Payment method: delete path: /domestic-vrp-consents/{consentId} reverses: VRP consent (stops future sweeps) window: null - operationId: DeleteEventSubscriptionsEventSubscriptionId api: Event Notification method: delete path: /event-subscriptions/{eventSubscriptionId} reverses: event subscription window: null - operationId: delete_consents__consentId_ api: Barclays Bank Ireland Account Information method: delete path: /consents/{consentId} reverses: AIS consent window: null - operationId: delete_payments_sepa-credit-transfers__paymentId_ api: Barclays Bank Ireland Payment Initiation method: delete path: /payments/sepa-credit-transfers/{paymentId} reverses: a SEPA credit transfer that has not yet executed window: null note: Berlin Group payment cancellation — the spec states no cut-off, and cancellation of an executed payment is not offered. irreversible: - 'Payment Initiation: all Create*Payments operations once the payment reaches ACSC/ACCC' - 'Card Application: application submission' - 'Payments (Barclaycard US): all payment operations' - 'Benefits Redemption: points redemption' dry_run_mode: supported: false note: 'No operation accepts a dry-run/validate-only flag. The nearest rehearsal is the OBIE consent resource: a TPP creates a *-consent first and can inspect its status before calling the matching execute operation, and Payment Initiation offers GET /{type}-payment-consents/{consentId}/funds-confirmation to check funds before executing.' pagination: style: HAL-style links envelope (UK Open Banking) response_fields: - Links.Self - Links.First - Links.Prev - Links.Next - Links.Last - Meta.TotalPages - Meta.FirstAvailableDateTime - Meta.LastAvailableDateTime request_params: - fromBookingDateTime - toBookingDateTime note: The Barclaycard US APIs and the open-data APIs declare no pagination envelope. request_id_tracing: headers: - x-fapi-interaction-id (UK Open Banking) - X-Request-ID (Barclays Bank Ireland) - Correlation-ID (Barclaycard US) echoed_in_response: true note: Three different correlation headers for three API families — an agent cannot use one convention across the estate. conditional_requests: supported: true request_headers: - If-Modified-Since - If-None-Match response_headers: - Etag - Cache-Control applies_to: - Product Details - FCA Service Metrics note: Only the OBIE open-data APIs support conditional GETs. versioning: in_url: true see: lifecycle/barclays-lifecycle.yml error_envelope: shape: OBError1 / OBErrorResponse1 media_type: application/json rfc9457: false see: errors/barclays-problem-types.yml rate_limit_signaling: status_code: 429 documented_in_contract: true operations_declaring_429: 99 response_headers: [] note: 99 operations declare a 429 "Too Many Requests" response, but no operation declares a RateLimit-*, X-RateLimit-* or Retry-After response header, and Barclays publishes no numeric limits. See rate-limits/barclays-rate-limits.yml. field_expansion: supported: false metadata_fields: supported: false note: The OBIE Meta block carries pagination/date-range metadata only; there is no customer-defined metadata field.